All articles

AccountCraft Journal

Shopify CCPA Compliance: 4 Admin Steps Using Customer Privacy API

Shopify CCPA compliance: use Customer Privacy API to block trackers, publish Do Not Sell/GPC opt out, and run a 45 day rights workflow.

13 min read

To meet CCPA/CPRA, update and publish a compliant privacy policy, provide a functional Do Not Sell or Share opt-out and honor Global Privacy Control signals, implement consent-aware cookie controls, and operationalize a 45-day rights-request workflow tied into your Shopify settings and app stack. These four moves close most of the gaps that trigger complaints or enforcement action, and each of them has a direct configuration point inside Shopify admin.


TL;DR:

  • Including an accurate, regularly updated privacy policy with specific disclosures helps demonstrate compliance and minimizes enforcement risks.
  • The “Do Not Sell or Share” link must be functional, prominent, and lead to an immediate opt-out, with GPC signals recognized as equivalent to manual requests.
  • Cookie banners and third-party scripts need to be configured to block tracking after opt-out, with ongoing verification through testing and network monitoring.
  • Consumer request handling requires timely responses within 45 days, verification of identity, and proper recordkeeping to defend against potential violations.
  • Vendor and app management should involve clear contractual obligations, role classification, and proactive deletion procedures to maintain compliance across the tech stack.

Accountcraft
Give Customers More Data Control
AccountCraft lets Shopify customers view and edit their information while supporting GDPR consent management within the platform.
Explore AccountCraft

Table of Contents

Quick checklist: the CCPA/CPRA essentials for Shopify stores

Most compliance gaps on Shopify stores trace back to a handful of missed steps. Working through them in order gets you from exposed to covered faster than chasing individual clauses of the statute.

  • Update your privacy policy to list categories of personal information collected, the purpose of collection, whether data is sold or shared, consumer rights, and at least two designated methods for submitting requests.
  • Add a homepage “Do Not Sell or Share My Personal Information” link that points to a page where the opt-out actually works.
  • Configure your cookie banner so non-essential trackers stay blocked until a shopper consents, and classify every script by what it does.
  • Build a data inventory, map every vendor that touches customer data, and keep audit-ready logs of requests and responses.

None of these are one-time tasks. Each needs an owner and a review date, because your app stack and marketing pixels change more often than your policy does.

How to update your Shopify privacy policy and where to place required disclosures

Cal. Civ. Code §1798.100 through §1798.135 sets out what your policy must say: categories of personal information collected, the business or commercial purpose for collecting it, categories of third parties it is disclosed to, consumer rights under the law, and the methods for exercising those rights, including opt-out links. Shopify’s own guidance confirms that notice has to be clear and given at or before the point of collection, typically through the published policy itself, covered under Shopify’s state privacy law documentation.

An automated policy template can cover the basics, but manually check any language around network intelligence or enhanced services, since those often involve data sharing the template does not fully describe.

  • Place the policy link in your footer on every page.
  • Add a California-specific rights section naming the request methods.
  • Link directly from that section to your opt-out page.

Pro Tip: Review your privacy policy every time you install or remove an app that touches customer or order data.

Implementing Do Not Sell / Do Not Sell or Share opt-out pages and respecting GPC

A cosmetic opt-out link that does not actually stop data sharing is one of the most common violations regulators and industry checklists flag, according to a CCPA compliance checklist from an industry association. Section 1798.135 requires a clear, conspicuous homepage link labeled “Do Not Sell or Share My Personal Information” that leads to a working opt-out, confirmed in California Code 1798.135.

  1. Place the link on your homepage with that exact label, not a euphemism.
  2. Build the opt-out page so the choice takes effect immediately and confirms the action to the shopper.
  3. Honor the opt-out for at least 12 months before asking the shopper to opt back in.
  4. Detect and respect Global Privacy Control signals the same way you process a manual opt-out click.
  5. Test both paths separately: a shopper who clicks the link, and a browser sending a GPC signal with no click at all.

Treating GPC as optional is a frequent enforcement trigger, since regulators consider it legally equivalent to an opt-out request.

Your cookie banner or consent management platform needs to talk to Shopify’s Customer Privacy API so that a shopper’s choice actually throttles the scripts running on your store, not just the banner’s own tracking. Shopify’s customer privacy settings documentation confirms the API can block or throttle third-party scripts and pixels in real time when a visitor opts out.

  • Inventory every third-party pixel running on your storefront and flag which ones constitute “sharing” for CPRA purposes.
  • Confirm blocked pixels stay blocked after opt-out, not just hidden from the banner.
  • Check analytics and ad platforms post-opt-out to verify data actually stops flowing.

Pro Tip: Run your store through an incognito browser with GPC enabled and watch your network tab for any pixel that still fires.

Handling consumer requests on Shopify: access, deletion, correction, verification, and timelines

The statute requires at least two designated methods for submitting a request, such as a web form and an email address, with a toll-free number required only in specific circumstances; a purely online business with a direct consumer relationship can rely on email and a website alone, under the official CCPA/CPRA statute.

  1. Verify the requester’s identity using information reasonably matched to your records.
  2. Respond within 45 days of receiving a verifiable request, with one possible 45-day extension for complex cases, as set out in the CCPA/CPRA statute.
  3. Deliver data in a portable, readily usable format covering the required lookback period, and keep a record of the verification steps and your response.
  4. Reach out to any app or service provider holding that customer’s data to complete deletion or access requests beyond your own storefront.

Documenting each step matters as much as completing it, since a request handled correctly but left unrecorded is hard to defend if challenged later.

Shopify-specific tools and developer options that help compliance

Shopify gives you a dedicated home for this work in Settings > Customer privacy, where automated templates and banner content live, according to Shopify’s configuration guidance. Shopify recommends reviewing and verifying that default content regularly rather than setting it once and forgetting it.

  • Configure the Customer Privacy API so third-party scripts check a visitor’s consent status before firing, which is more reliable than banners that only hide content visually.
  • Use manual exclusions in Shopify Audiences when a customer opts out, understanding that exclusion only stops sharing going forward.
  • Keep a provenance log for each audience you build, since Shopify’s Audiences privacy documentation confirms manual exclusion does not retroactively scrub data from audiences already generated.

Vendor and app management: contracts, service-provider terms, and cross-system deletion

Every app connected to your store that touches personal information needs a role classification: service provider, or a party that constitutes a sale or share under CPRA. Shopify’s own documentation notes that merchants must proactively identify and contact external systems for deletion, since Shopify does not automatically propagate erase requests to non-Shopify apps.

  • List every app with data access and classify its role.
  • Add or update contract language requiring vendors to assist with verifiable requests and restrict their own use of the data.
  • Document each deletion request sent to a vendor and track confirmation of completion.

Pro Tip: Revisit your vendor list every time you add a new app, not just once a year.

Perspective: operationalize privacy as ongoing store administration

Privacy work on Shopify tends to live wherever customer data lives, which is why we built AccountCraft around editable customer account pages that keep data inside Shopify rather than scattered across themes and scripts. Our Block Builder lets merchants add components like wishlists and personalized fields without touching theme code, and consent management is built into every account page by design.

Steps to handle minor’s data and special protections if applicable

Any Shopify store that knowingly collects personal information from a shopper under 16 faces stricter consent rules than the general opt-out framework. For a minor under 13, the statute requires affirmative authorization from a parent or guardian before any sale or sharing of that data occurs. For a minor between 13 and 16, the minor must provide affirmative opt-in consent themselves before their data can be sold or shared.

If your store sells products aimed at a younger audience, or if your checkout and account creation flows do not screen for age, treat every account as unknown and apply the stricter standard rather than assuming adult status. Practical steps include adding an age-confirmation step at account creation, routing any account flagged as a minor away from default data-sharing settings, and training staff who handle customer service tickets to recognize and escalate a request involving a minor’s data rather than processing it under standard rules.

Age-based consent decision flow for minor data

Keep a separate log for opt-in consent collected from minors or their guardians, since the burden of proof in a dispute falls on the business to show that consent was properly obtained before any sale or sharing took place. If your store does not knowingly market to or collect data from anyone under 16, document that determination as part of your privacy policy review, since regulators have asked businesses to show their reasoning, not just their conclusion.

Guidance on training staff on CCPA compliance specific to Shopify store operations

A privacy policy and a working opt-out page only hold up if the people running your store understand what to do when a request actually arrives. Customer service staff are usually the first to see a deletion or access request, whether it comes through a contact form, a support email, or a live chat widget, and they need a clear script for what counts as a verifiable request versus a routine question.

Train staff to recognize the specific language a CCPA request uses, since a shopper will rarely cite the statute by name but will ask to “delete my data” or “stop selling my information.” Build a short internal runbook that routes any such message to whoever owns privacy compliance rather than letting a support agent close the ticket without escalation. Make sure whoever manages your Shopify admin knows where Customer Privacy settings live and how to check that the opt-out page and cookie banner are still functioning after a theme update or app installation, since those changes are a common point where privacy controls silently break.

Revisit training whenever you onboard a new app that collects customer data, since the person answering support tickets is the one who needs to know that a new tool exists and what role it plays before a request involving that tool ever comes in.

Guidance on training staff on CCPA compliance specific to Shopify store operations — overview diagram

Details on consequences and penalties for non-compliance to motivate thorough implementation

Non-compliance carries both legal and reputational cost. Enforcement attention has concentrated on a specific set of failures: opt-out links that exist but do not functionally stop data sharing, ignoring Global Privacy Control signals, and privacy notices that omit required disclosures, according to the industry compliance checklist. Failing to honor GPC is treated the same as ignoring a manual opt-out request and can constitute a violation on its own.

Beyond regulatory risk, a broken opt-out or an incomplete privacy policy erodes the trust that keeps shoppers coming back, particularly for a store built on repeat customers and an email list. A merchant who treats privacy as a line item to finish once rather than a setting to monitor is the one most likely to get caught out when an app update changes how a pixel fires or when a theme change quietly removes the footer link to the privacy policy.

Editorial take on building a Shopify-first compliance workflow

The checklist version of CCPA compliance gets treated like a form to fill out once, and that is the biggest misread of what the law actually demands. A privacy policy published in January and never revisited is already stale by the time you install your third new app that quarter. The conventional advice leans heavily on documentation: write the policy, add the link, done. What actually holds up under scrutiny is the operational layer underneath it, the Customer Privacy API calls that block a script in real time, the vendor contract that obligates an app to help with a deletion request, the log that proves you responded within 45 days.

If you prioritize one thing first, make it the technical enforcement of opt-out choices over the wording of your policy. A beautifully written privacy policy sitting next to a cookie banner that does not actually stop tracking is worse than a plain one backed by a banner that works, because the gap between promise and practice is exactly what draws complaints.

— Barikreativa

How AccountCraft helps merchants reduce compliance friction

Rights requests get harder to manage the more your customer data sprawls across themes, apps, and spreadsheets. We built AccountCraft so customer data stays inside Shopify, with editable fields and consent controls your shoppers can manage themselves from their own account page.

Accountcraft

  • Keep customer data inside Shopify instead of scattered across third-party tools.
  • Give shoppers editable fields and visible consent controls on their own account page.
  • Build compliant account experiences with a Block Builder, no theme edits required.

Fewer places data lives means fewer gaps when a deletion or access request comes in. See our Free, Pro, and Plus plans and find the fit for your store.

FAQ

What is required for CCPA compliance?

A business subject to CCPA must disclose what personal information it collects and why, provide at least two designated methods for consumers to submit requests, and respond to verifiable requests within 45 days, with one possible 45-day extension, per the CCPA/CPRA statute. It also must post a working “Do Not Sell or Share My Personal Information” link and honor Global Privacy Control signals the same way.

Is there a class action lawsuit against Shopify?

This article focuses on what individual Shopify merchants need to do to meet CCPA and CPRA obligations for their own stores, not litigation history involving Shopify as a platform. Merchants remain responsible for their own store’s compliance regardless of any separate legal matters involving third parties.

Is Shopify still worth it in 2026?

That question depends on factors well outside CCPA compliance, like pricing, app ecosystem, and your specific business needs, and falls outside what this guide covers. From a privacy standpoint, Shopify does provide built-in tools like Customer Privacy settings and the Customer Privacy API that make compliance more manageable than building those controls from scratch.

Are Shopify stores ADA compliant?

ADA compliance is a separate legal area from CCPA and CPRA privacy requirements, and Shopify stores are not automatically compliant with either simply by using the platform. Each merchant is responsible for configuring their own store, theme, and content to meet applicable accessibility and privacy obligations.

How do I verify a customer’s California residency for a CCPA request?

Reasonable verification typically relies on matching information the requester provides against your existing customer records, such as order history, email, or account details tied to a California address. There is no single mandated method, so document whatever reasonable steps you take as part of your audit-ready records.

Sources

The points above draw on the official CCPA/CPRA statute, California Code provisions on opt-out requirements, and Shopify’s own Help Center documentation on privacy settings and data requests, all linked throughout this article. Consult a qualified attorney for guidance specific to your store’s situation.

Written with BabyLoveGrowth’s AI tools